Evidence of Program Execution Flashcards

Investigate areas of Program Execution

1
Q

Define UserAssist

A

UserAssist is where GUI-based programs launched from the Desktop are tracked in the launcher on a Windows system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Provide the UserAssist Location

A

NTUSER.DAT HIVE (NTUSER.DAT\Software\Microsoft\Windiows\CurrentVersion\Explorer\UserAssist\GUID\Count

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Describe BAM/DAM

A

Windows Background Activity Monitor - Provides full path of the executable file that was run on the system and the last execution date/time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Provide the BAM/DAM location

A

WIN10 SYSTEM\CurrentControlSet\Services\bam(dam)\UserSettings\SID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Describe RecentApps

A

Program execution launched on Win10 system is tracked in the RecentApps key.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Provide the RecentApps location

A

WIN10 NTUSER.DAT\Software\Microsoft\Windows\Current Version\Search\RecentApps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe ShimCache

A

Tracks executable’s file name, file size, last modified time. Any executable run on the Windows system can be found in this key. You can use this key to identify systems a specific malware was executed on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Provide the ShimCache location

A

WIN7/8/10 SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Describe Jump Lists

A

Windows 7 to 10 task bar (Jump List) is engineered to allow users to jump or access items they have frequently or recently used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Provide the Jump Lists location

A

WIN7/8/10 C:\USERPROFILE\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Describe Prefetch

A

Increases performance of a system by pre-loading code pages of commonly used applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Provide the Prefetch Location

A

C:\Windows\Prefetch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Describe AmCache.hve

A

Entry for every executable run, full path information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Provide the AmCache.hve location

A

C:\Windows\AppCompat\Programs\Amcache.hve

How well did you know this?
1
Not at all
2
3
4
5
Perfectly